Skip to content
Regulation and policy

Feedzai launches Farol AI agent for bank fraud teams

Feedzai has launched Farol, an AI agent embedded in bank fraud systems that drafts suspicious activity reports and analyses detection rules — but UK reporting duties still rest with human officers.

By

Published
A conveyor belt carries a row of paper case files towards a desk where a hand holds an ink stamp above a single open file, with more files stacked behind on the belt.

Feedzai has launched Farol, an artificial intelligence agent designed to sit inside a bank's existing fraud-detection systems and take on part of the investigation work that analysts currently do by hand. The company demonstrated the agent at its Feedzai Fusion London event on 23 September 2026 and issued a formal launch announcement the following day, 24 September 2026.

The launch matters to UK banks because Farol touches some of the most sensitive work a financial institution does: retrieving and summarising fraud alerts, judging whether a detection rule is working, and drafting the paperwork that can lead to a suspicious activity report (SAR) — a disclosure that, under the UK's anti-money-laundering regime, a firm's nominated officer must assess and submit to the UK Financial Intelligence Unit (UKFIU) where an internal disclosure gives rise to knowledge, suspicion or reasonable grounds for suspicion of money laundering or terrorist financing. Feedzai's London event brought together speakers from HSBC and Lloyds Banking Group, alongside reported participation from Monzo and Nationwide, giving the launch a strong UK audience even though none of those institutions is confirmed to use the product.

The central question for UK readers is not whether Farol can save time, but where the line falls between a machine drafting a document and a human deciding what it says. In UK anti-money-laundering law, that judgement remains the responsibility of the institution's nominated officer, and the FCA's Financial Crime Guide sets out examples of good practice for firms using automated monitoring systems — neither is defined by a vendor's product design.

What Farol is built to do

Farol is not a standalone chatbot. Feedzai says it is embedded in Feedzai RiskOps Studio, the company's existing fraud-operations platform, rather than offered as a separate general-purpose AI interface. According to Feedzai's launch announcement and FinTech Futures' report from the London event, the agent has four broad functions:

FunctionWhat Feedzai says it does
InvestigationsRetrieves and summarises alert data to give analysts case context
Risk strategyAnalyses fraud-detection rule sets, flags rules that create noise without catching fraud, and recommends sharper thresholds
Platform assistanceAnswers analyst questions about the platform
SAR draftingCompiles and drafts suspicious activity reports

These are Feedzai's own descriptions of the product. None of the reviewed sources includes an independent technical audit, a demonstration transcript, or an outside benchmark of how the agent performs any of these tasks.

How it is meant to fit inside a bank's systems

Feedzai says Farol operates within each financial institution's own environment, so information it surfaces and insights it generates remain inside the customer's estate rather than leaving it. The company frames this as an extension of existing risk workflows rather than a new, separate system that banks would need to integrate from scratch.

This is an architecture and data-residency claim made by Feedzai. The research behind this article did not find a published technical assurance document, deployment diagram, or independent audit that verifies where the boundary between "inside the institution's estate" and any external processing actually sits, including which underlying AI model or models power the agent or where inference is carried out.

The efficiency claims, and what is missing

Feedzai's announcement attaches specific figures to Farol's capabilities:

  • 68% of financial institutions are actively testing agentic AI, Feedzai says, citing its own research.
  • 20% reduction in alert-handling time, Feedzai says.
  • Up to 12 times faster SAR drafting, according to Feedzai.

All three are vendor-supplied figures. The announcement does not disclose a sample size, a baseline, a test period, the institutions involved, or independent validation for any of them. "Up to 12 times faster" describes a maximum, not a typical result, and none of the figures says anything about the accuracy or completeness of Farol's output — a material gap given that one of its stated jobs is drafting a document that can trigger a statutory report.

Four UK banks in the room, not four customers

FinTech Futures reported that HSBC, Lloyds Banking Group, Monzo and Nationwide featured among the speakers at Feedzai Fusion London. Feedzai's own event page independently names speakers from HSBC and Lloyds Banking Group.

This is contextual evidence about who attended and spoke at a Feedzai conference. It is not evidence that any of the four institutions uses, pilots, or has agreed to buy Farol. The research behind this article found no statement from HSBC, Lloyds Banking Group, Monzo or Nationwide confirming adoption, and no procurement or deployment record. Readers should treat the banks' presence at the event as event participation and speaking commitments, not as a customer relationship or an endorsement of the product.

Who keeps control of the final decision

FinTech Futures reported that Feedzai's chief product officer said the final step in sensitive fraud work remains with financial institutions, which are introducing guardrails before allowing the agent greater autonomy — described in the reporting as retaining the "last mile" of human judgement.

That sits alongside language in Feedzai's own announcement referring to Farol's "autonomous execution capabilities." The two descriptions are not easy to reconcile: one emphasises a human checkpoint before anything happens, the other emphasises the agent acting on its own. Neither Feedzai's release nor the event reporting reviewed for this article specifies exactly which Farol actions can proceed without an analyst's sign-off and which remain recommendations or drafts awaiting review. That detail — whether the agent can alter a live detection rule, close an alert, or take any action beyond drafting text — has not been published.

The UK reporting regime Farol drafts into

Where Farol's output is a draft SAR, it enters a UK legal framework that does not change because a document was produced faster. HM Revenue & Customs guidance, accessed on 26 September 2026, states that a nominated officer who receives an internal disclosure must assess whether it gives rise to knowledge, suspicion or reasonable grounds for suspicion, and must submit a SAR to the UKFIU — which sits within the National Crime Agency — where those grounds exist. A faster or more polished draft does not remove that officer's obligation to make the underlying judgement.

The National Crime Agency is explicit that a SAR is not the same as a report of fraud or another crime; it is a specific anti-money-laundering and counter-terrorist-financing disclosure with its own legal basis. The NCA's current page states that the UKFIU receives more than 850,000 SARs a year and holds more than 4.5 million in its secure central database, though the page does not specify the exact reporting year those figures cover. Failure to disclose where the statutory grounds for suspicion exist can, on conviction on indictment, carry a penalty of up to five years' imprisonment, a fine, or both, according to NCA and HMRC guidance.

The FCA's Financial Crime Guide, updated through Policy Statement PS24/17 on 29 November 2024, sets out what it regards as good practice for firms using automated detection systems: tailoring rules to the firm's own risk profile, testing outcomes, keeping accessible records of decisions, updating parameters appropriately, and — significantly for a tool that analyses and recommends changes to detection rules — understanding what the automated system actually detects. None of this guidance mentions Farol by name, and no FCA approval or endorsement of the product was found in the material reviewed for this article. It is regulatory context describing good practice, not a certification Feedzai has received.

What to watch next

Several open questions determine whether Farol changes how UK banks handle fraud and money-laundering reporting in practice, or remains a conference demonstration. These include whether any UK institution formally adopts the product, what technical and security documentation Feedzai publishes on data handling and model use, whether Farol's SAR drafting is configured for UKFIU-specific fields and glossary codes, and whether Feedzai or any customer publishes independently verified performance figures rather than vendor-supplied ones. Readers wanting the primary UK rules on suspicious activity reporting can consult the National Crime Agency's guidance directly, and firms assessing automated detection systems can refer to the FCA's Financial Crime Guide.

Sources

  1. Feedzai Fusion London (opens in a new tab)

    Feedzai · Accessed

  2. AMLG11100 - Guidance for all sectors: Reporting Suspicious Activity (opens in a new tab)

    HM Revenue & Customs · · Accessed

  3. Suspicious Activity Reports (opens in a new tab)

    National Crime Agency · Accessed

  4. PS24/17: Financial Crime Guide changes (opens in a new tab)

    Financial Conduct Authority · · Accessed